Tampilkan postingan dengan label corporate espionage. Tampilkan semua postingan
Tampilkan postingan dengan label corporate espionage. Tampilkan semua postingan

Selasa, 06 Maret 2012

Revealed: Technical Surveillance Threats

Revealed: Technical Surveillance Threats


Spy Cam 101

Not long ago while on assignment, I was asked "How many times do you actually find technical surveillance threats?"
My answer was "Well, I would tell you but then I would have to...." Just kidding,  The real answer is more often than you would think..
Although, not every technical surveillance threat involves finding a device. It can also can mean discovering a technical surveillance vulnerability. Like for instance, the allowance of cellular devices (w/ cameras) or iPads in conference rooms and during high level meetings. Or, the allowance of digital recorders within these areas, just to name a few.

It's not always "James Bond" spy gear that turns up during a sweep.

But every now and then, I still discover a "surprise" that may (or may not) have been left behind...on purpose.

For example, take this pen & pencil holder discovered during the wee hours of the morning while sweeping the "Presidential Suite" of one of our clients facilities.


Plain looking enough, but take a closer look... Through our Thermal Imaging Camera... Notice that hot spot? So did we...It turned out to be a hardwired Spy cam, with audio....Here's another look..


This was only one of the technical surveillance threats found during this assignment. Yes, you heard me right, only one of several threats found...

So, the short answer is YES, technical surveillance threats (although crude) like the above are used for intel collection purposes by your adversaries. i.e.; disgruntled employee, competitor, corp spy, eavesdropper, etc.
So be aware, these types of surveillance threats could be lurking closer than you might think...

If you don't mind me asking, When was your last TSCM Sweep?  Not Sure?  Contact Me here. I can help.

Stay tuned for the next "reveal"....JDL

Kamis, 23 Februari 2012

IT and espionage on Wall Street

economist.com

An overturned conviction creates uncertainty about what constitutes a crime


ASK a programmer at an investment bank where he works, and the answer will often simply be “Wall Street”. Isolated from clients and—it was once thought—assets with proprietary value, technologists bounce from firm to firm, from one high-rise building to another.
To this footloose community, the case of Sergey Aleynikov, a Goldman Sachs programmer, came as a shock. Mr Aleynikov was convicted in December 2010 of stealing code tied to Goldman’s lucrative high-speed proprietary-trading operations for use by a new employer. On February 16th, after he had spent nearly a year in prison, three judges in a federal appeals court unanimously reversed his conviction in a hearing that lasted just a single morning. Their written opinion is now eagerly awaited.
Mr Aleynikov admitted to taking code with him on his way out of Goldman, but argued successfully that this did not constitute a crime, or, to be more specific, a federal crime. He benefited from the help of a thorough lawyer, who adroitly knocked down two key claims. Because the computer trading system was not licensed or offered for sale, claimed Kevin Marino, the defendant’s lawyer, it was not a product to be bought or sold for interstate commerce, a key provision for a federal case. Because computer coding constitutes intangible intellectual property, Mr Marino said, it did not qualify under the goods, wares or merchandise components that are protected under the corporate-espionage act.

Selasa, 14 Februari 2012

Traveling Light in a Time of Digital Thievery

Note: Having recently traveled to China, I can attest to Mr. Lieberthal's concerns....Do yourself (and your company) a favor, Just accept the fact that you "will" be collected against...and take Mr. Lieberthal's advice...very seriously.  JDL

nytimes.com

SAN FRANCISCO — When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film.
He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop.”
What might have once sounded like the behavior of a paranoid is now standard operating procedure for officials at American government agencies, research groups and companies that do business in China and Russia — like Google, the State Department and the Internet security giant McAfee. Digital espionage in these countries, security experts say, is a real and growing threat — whether in pursuit of confidential government information or corporate trade secrets.


More...

Jumat, 30 Desember 2011

Cameramaker Red claims espionage

variety.com
In a saga worthy of a Hollywood thriller, allegations of email hacking and industrial espionage have surfaced in the camera industry in a lawsuit filed by digital camera maker Red against rival Arri.
In the suit filed Dec. 21 in federal court in Orange County, Calif., Red accuses Arri of stealing technical details and development plans for Red cameras, giving Arri an unfair advantage.
Much of Red's complaint rests on facts revealed in an August plea deal between federal prosecutors and former Arri executive Michael Bravin, who is also a defendant in the suit. Bravin pleaded guilty to a misdemeanor charge of email hacking, admitting as part of the deal that he accessed the email account of Band Pro chief executive Amnon Band.
Bravin, who according to his LinkedIn profile worked for Band Pro for more than 16 years, resigned as Band Pro's chief technology officer to become Arri's VP of market development for digital camera products in January 2010.
From around December 2009 through June 2010, Bravin had access to Amnon Band's email account, as Bravin has admitted. Under his plea deal, he was to serve two months in jail and pay $20,000 in restitution to Band Pro as well as legal costs. Bravin now lists himself on LinkedIn as principal at the Digital Picture Co.
In its complaint, Red asserts that during the time Bravin was hacking Band's email account, Band Pro and Red were discussing a possible joint venture. Red says Band's emails contained detailed descriptions of the technology used in Red's cameras and Red's plans for introducing new models and features.
Red alleges that Bravin passed that information to Arri, giving Arri an unfair competitive advantage, especially with respect to the launch and marketing of the Arri Alexa camera. The Alexa was released in 2010 and is seen as a direct competitor to Red's Epic.

Selasa, 22 November 2011

Compliance vs. Security: The Multiple Dimensions of Corporate Espionage

sys-con.com

You've spent months fixing the red items on an internal audit report and just passed a regulatory exam. You've performed a network vulnerability assessment and network pen test within the last year and have fixes in place. You've tightened up your information security policy and recently invested in a security information and event management (SIEM) solution. You're secure, right?
Put yourself in the shoes of a criminal. He knows that most security programs focus on regulatory compliance. He knows that IT departments have limited budgets. He also knows that you must defend against an almost unlimited number of attack vectors, while he just has to find one way in.
How do you protect against a sophisticated, motivated criminal? A professional spy who has targeted your company's trade secrets? A skilled insider with a specific purpose in mind? These types of people know that information comes in many forms, not just electronic, and they are trained to exploit any vulnerability. An effective information security program must incorporate more than just traditional pen tests and vulnerability assessments. 

Corporate espionage is on the rise for multiple reasons: the down economy, frequent job changes, and even governments that boost their economies through acquisition of trade secrets. In most cases, the end product is not as valuable as obtaining the means of production, the research and development, or the "know-how." This type of information will help to cut down on development costs and aid in the long-term production of a particular good. In the end, a company must get the best product to market first, at the best cost, through maneuvering around the competition.


Senin, 31 Oktober 2011

Cyber spy campaign targets chemical industry: Symantec

(AFP)
SAN FRANCISCO — US Internet security firm Symantec on Monday exposed a cyber spying campaign targeting trade secrets at top chemical firms and linked the industrial espionage to a man in China.
At least 48 companies, including some that make advanced materials for military vehicles, were targeted in a campaign Symantec dubbed "Nitro" given the type of information at risk.
"Attacks on the chemical industry are merely their latest attack wave," Symantec security response team members Eric Chien and Gavin O'Gorman said in a report released on Monday.
The attacks targeted NGOs supporting human rights from late April to early May before switching to the motor industry, according to the report.
Major chemical firms, mainly in the United States, Britain, and Bangladesh, came under fire by cyber spies from late July to mid September, Symantec said.
Nitro was aimed at stealing intellectual property for competitive advantage, according to Chien and O'Gorman.
Attackers researched firms, sending selected workers booby-trapped emails that, once opened, secretly infected computers with malicious "Poison Ivy" software designed to steal information.
While various ruses were used to trick workers into opening email attachments to unleash spy software in machines, a typical pretext was to fake a meeting invitation from an established business partner.
Another tactic used by cyber spies was to send employees email purporting to be a security software update that needed to be installed in computers, according to Symantec.
Poison Ivy code was written by a Chinese speaker and Nitro attacks were traced to a server located in the United States but owned by a "20-something male" in the Hebei region of China, the report said.

Jumat, 28 Oktober 2011

German secret police arrest elderly Spies "Mr. & Mrs. Smith"

pravda.ru

Last week, the German counterintelligence arrested the spouses, who were suspected of industrial espionage. It was said that the spouses were working for Russia's Foreign Intelligence Service.
The German media do not have the right to expose the last name of the suspects. The spies, named only as Heidrun and Andreas A., have not been charged yet. Russian mass media say that the last name of the spouses is Anschlag. It was said that the two spies arrived in the Federative Republic of Germany 20 years ago from South America. It just so happens that the KBG recruited them during the time when officer Vladimir Putin was serving in Germany.
We would like to remind here that the Foreign Intelligence Service declared itself to be the official successor of the First Principal Directorate of the KGB in December 1991. It was a foreign intelligence department, whereas Putin always served in counterintelligence. To put it simply, Putin's job was to neutralize the colleagues of the detainees - he did not recruit and infiltrate anyone. Therefore, the sitting prime minister knew nothing about the activities of the two spies.
Heidrun and Andreas, who held Austrian passports, were living in the south-west of the FRG, in Landau, from 2002 to 2010. According to the Rheinpfalz newspaper, Andreas was collecting industrial secrets and sending them to Russia's Foreign Intelligence Service. Andreas, a professional machine-builder, was working at the firm called Faurecia (car supplies). He also owned an innovation center in Rheinland-Pfalz province. 
At the end of 2010, the spies were supposed to move to Marburg, where they rented a one-room house. Heidrun, 51, was arrested in that house. The woman was supposedly sitting in front of the transmitter and was about to receive a code telegram. Andreas, 45, was conducting his illegal activities at the time when he was officially serving as a car supplier in Heuchelheim in the state of Hesse. The man was arrested last week on Tuesday night by the federal department of criminal police and GSG 9 antiterrorist department.
The Rheinpfalz reporters found out that the married couple spoke German with an east-European accent. The couple also has a 20-year-old daughter, a student of a medical college in Marburg.

Israel Convicts Conspirator Who Wiretapped Michael Cherney

israelnewsagency.com


Jerusalem, Israel --- October 26, 2011 .... On October 24th the Jerusalem Magistrate's Court in Israel convicted far-right activist Avigdor Eskin of ordering the illegal wiretapping of associates of Israel businessman and philanthropist Michael Cherney (Mikhail Chernoy).
The plea bargain consists of a penalty of six months of community service, probation and a fine of NIS 20,000.

According to the original indictment, filed in January 2011 by the Israel State Attorney's office, Eskin was contacted in 2007 by a Russian citizen, Alexei Drobashenko, who asked him to gather information about Michael Cherney in order to use it in a smear campaign.
At that time Alexei Drobashenko was the head of the External Relations Department at Basic Element, a financial and industrial group that belongs to Oleg Deripaska. Deripaska and Cherney are former partners in an aluminum business. In 2006 Cherney filed a law suit against Oleg Deripaska in the UK's High Court.
Cherney is seeking a 20 percent stake in RUSAL, a multinational aluminum producer. The trial is expected to go ahead in April 2012.
In February 2008, Cherney filed a suit in a Tel Aviv court, accusing a group of 10 conspirators, allegedly funded by Oleg Deripaska, of illegal wiretapping, hacking the computers of his charity fund - The Michael Cherney Foundations, publishing slanderous articles, harassing him with insulting graffiti and leaflets, hiring a UK PR company to plant hoaxes about Cherney into the UK media and Wikipedia.
The purpose of that smear campaign was allegedly to derail Cherney's lawsuit against Deripaska in UK's Commercial Court.
Aviv Mor, an Israel private investigator, together with another PI, Rafael Pridan, carried out wiretaps against Cherney's secretary Elena Skir and another of Cherney's associates, the indictment contended.
The indictment further charged that Eskin was the link between Mor and Pridan and Drobashenko, that he paid them each NIS 50,000 in cash for their services and that he also received translations of the wiretapped conversations.

Russian spies suspected of stealing auto secrets from Germans

inautonews.com

A married couple was arrested in the German town Michelbach, suspected of stealing secrets from German car manufacturers, after it emerged one of them worked in the auto industry for the past 20 years.
German prosecutors stated that the couple had been arrested on accusations of spying for an unspecified foreign intelligence service, which media identified over the weekend as Russia’s Foreign Intelligence Service.
According to English-language German newspaper The Local, …
“intelligence service sources say the man, named only as Andreas A., had worked for Faurecia, one of Germany’s top car part manufacturers which supplies major companies including Volkswagen, Renault, Toyota and Ford,” where he is thought to have engaged in “industrial espionage.”
Andreas A., who was identified by the Daily Mail as Andreas Anschlag, 45, is believed to have been living in Germany for the past 20 years with his wife Heidrun, 51, “having used fake passports to enter the country, and then setting themselves up as a family, even having a daughter who is now said to be 20 years old and studying medicine in Marburg.”
The Moscow Times reports that Heidrun Anschlag “was caught by investigators while listening to encrypted radio messages” from Russia on a short-wave, which experts tell the paper is “bizarre” in this day and age, when internet and other forms of communication are available.
Russian newspaper Iswestija (via The Local) quotes a “Russian intelligence agent [as] saying the couple were long retired from the spy business and that they may have been used to transfer information, ‘like a kind of letter box.’”

Minggu, 23 Oktober 2011

FBI: Tech firms face spy risk

democratandchronicle.com


Kexue Huang, a scientist and native of China, pleaded guilty last week in a federal court to swiping millions of dollars worth of trade secrets from Dow Chemical Co. and Cargill Inc. for other people doing research in Germany and China.


A federal jury last month ordered South Korea's Kolon Industries to pay DuPont Co. $920 million for stealing trade secrets regarding synthetic fibers used in such products as Kevlar body armor. A former DuPont engineer hired by Kolon, Michael Mitchell of Virginia, was sentenced in March last year to 18 months in prison for theft of trade secrets for passing on key DuPont data to Kolon.

And area technology companies are likely fooling themselves if they think they're not in the cross-hairs of such spy efforts, according to the Federal Bureau of Investigation. "If you haven't been a victim yet, it's because you have been and you don't know it, or you will be," Barry W. Couch, a special agent with FBI's Buffalo division, told a conference room full of area optics industry executives last week. "Don't be blindsided."

Chili's Sydor Optics played host as the FBI spent a handful of hours talking about counterintelligence and economic espionage issues, with handouts and a video presentation all revolving around the message that companies are under siege by foreign economic competitors, often with explicit help from foreign governments.

Optics in particular "is a targeted industry," said FBI special agent Chad Kaestle. Other frequently targeted technologies include sensors, aeronautics and marine systems.

Jumat, 07 Oktober 2011

SpearTip’s Top Cyber Counterespionage Expert Gives TV Interview on TRICARE Data Theft

prweb.com

Doubts custodian’s assurances. Fears possible extortion of military employees whose personal medical data was taken.


St. Louis, Missouri (PRWEB) October 07, 2011
Jarrett Kolthoff, CEO of Cyber Counterespionage firm SpearTip, was interviewed by CBS-affiliate KMOV about the recent theft of two-decades-worth of medical data on nearly five million military personnel. Part of the interview was broadcast. An expansion of that interview is included here.
The custodian of the records, Science Applications International Corporation (SAIC), reported the data breach had occurred two weeks earlier, when numerous back-up tapes were assertively stolen in a break-in of an employee’s car, while the tapes were in transit across town.
SAIC downplayed the breach, saying no financial information was involved, although SAIC acknowledged the tapes contained sensitive medical information. SAIC discounted harm from the loss of this information, saying: “The risk of harm to patients is judged to be low despite the data elements involved, since retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure.” Kolthoff said this statement is not an assurance that data was encrypted. The news report indicated that only “some” of the tapes were encrypted.

Rabu, 05 Oktober 2011

Social media for corporate networking or corporate espionage?

informationweek.in

Today, corporates are looking at social media like Twitter, LinkedIn and Facebook to broaden their online outreach. In a session at INTEROP Mumbai 2011, Abilash Sonwane, Senior-VP, Elitecore Technologies, talked about how social media networks are the next frontier of corporate espionage



Around 13 percent of corporate losses occur due to corporate espionage, as per a recent KPMG report. The number is less as most of the companies usually don’t admit it. In a session at INTEROP Mumbai 2011, Abilash Sonwane, Senior-VP, Elitecore Technologies, talked about how social media networks are the next frontier of corporate espionage.
Today, corporates are looking at social media like Twitter, LinkedIn and Facebook to broaden their online outreach. As per Nielsen Online study, social networking is now officially more popular then e-mail. Considering the popularity of social media among corporates, Elitecore Technologies did a research on 20 companies to find out how social media can be used for corporate espionage.
To conduct the research, Elitecore selected companies that were active on social media from a mix of industries and geographies. The company found out that though on one hand social media can enable an enterprise to enhance its relationship with customers, on the other hand it can adversely affect a company’s reputation.

More...

Jumat, 30 September 2011

kmov.com

(KMOV) -- Wednesday night, TRICARE, the health care program for millions of military members, retirees, and their families announced a data breach that affects an estimated 4.9 million people.

Read TRICARE's statement here: www.tricare.mil/mybenefit/Download/Forms/DataBreach_PublicStatement.pdf

Science Applications International Corporation reported that one of its employees was driving backup computer tapes from one federal office to another in San Antonio, Texas. At one point, the car was broken into and the backup tapes were stolen. SAIC says it won't disclose how many tapes were taken, but says only "some" were encrypted.

The tapes that were lost included names, Social Security numbers, addresses, and medical treatment information of patients who were treated at San Antonio military treatment facilities (or patients who have had lab work processes there) from 1992 until September 7, 2011.

TRICARE and SAIC say they are working to identify all the beneficiaries whose information may have been lost and notify the affected people. TRICARE says that the risk of harm to patients is low because the thief would have to have access to specific hardware and software and know how to pull the data from the tapes.

Jarrett Kolthoff, who runs a cyber security firm called SpearTip, LLC, says people should be concerned.

"It doesn't take a rocket scientist to grab that information and than use that data in a nefarious manner," said Kolthoff.

"If it was unencrypted, my concern would be the leverage that somebody could use against individuals."

More...

Rabu, 28 September 2011

The Best Spies Money Can Buy

darkreading.com
Security firms have found evidence that espionage agents are buying time on leased botnets: Will cybercriminals services lead to more efficient spying?

During the past decade, cybercriminals have specialized in the various tasks needed to compromise computers, steal data, and make money. Now, more elusive nation-state attackers could be using rented botnets and cybercriminal services to streamline their own operations, security experts say.

In June, security firm FireEye detected evidence of such a connection when it found instances of a remote-access Trojan whose code seemed to have been reused to infect machines with fake antivirus software. In another incident, cybercriminals sold access to compromised military and government computers, allowing would-be cyberspies to get direct access to their targets, says Darien Kindlund, senior staff scientist at FireEye.

The two examples are part of a building body of evidence that suggests attackers representing what the military and security industry refer to as the advanced persistent threat (APT) are not shying away from using criminals' resources to help them in their missions.

"If military and government hosts are being sold on the black market, who are the most likely buyers -- spammers?' No, they could buy something cheaper on a different network. But for APT?'Yes, it meets their mission objectives," Kindlund says.

More...

Selasa, 20 September 2011

Defence contractor warns of false cyber security beliefs

crn.com.au

Four 'mindsets' that trip up specialists.

BAE Systems Australia's cyber security head has warned against four mindsets preventing security specialists from effectively dealing with cyber threats.

According to the defence contractor's Tim Scully, an overemphasis on all-encompassing defensive measures or on compliance with standards or regulations could be counterproductive.

Scully, who was also the chief executive officer of BAE subsidiary Stratsec, chaired a work group on Cyber Threat and Fortress Mentality at the second national cyber warfare conference in Canberra this week.

Fortress mindset

He described the "fortress mindset" as the traditional approach to security, where specialists aimed to keep all threats outside of their networks.

Defensive measures in a "fortress" approach focused on systems and infrastructure rather than focusing on protecting the organisation's most valuable information.

That approach was as naïve as thinking that everything inside the network was secure, he said.

“If your network is connected to the Internet, and you have something of value to a threat actor, you are likely already compromised," he said.

More...

Minggu, 18 September 2011

Espionage Research Institute (ERI) 2011 Conference


Espionage Research Institute (ERI) 2011 Conference

The 2011 ERI Conference brought together a group of leading edge counterintelligence practitioners that respond to crisis situations and espionage incidents from both foreign and domestic threats.

FOR IMMEDIATE RELEASE

Sept 18, 2011 - The 2011 ERI Conference brought a group of these counterespionage agents out of the shadows for a brief moment to share information with their brethren. The threats levied against corporations from either electronic surveillance (bugs) or the latest threats from malware (Advance Persistent Threats) require these specialists to keep abreast of the latest threats. Adhering to ERI’s motto: "The Biggest Mistake That We Can Make Would Be To Miss The Changes", and their membership meets annually to ensure they remain aware of the changes in the espionage industry and can effectively detect threats.

This year’s keynote address from Jarrett Kolthoff, CEO – SpearTip, a former U.S. Counterintelligence Agent, addressed the threats levied against corporations from both foreign and domestic competitors. Mr. Kolthoff provided insight on how many corporations are responding to these incidents and are holding the rogue employee and/or competitor accountable for their actions.

Other presenters at the conference brought some of their latest technology, such as the OSCOR GREEN from Research Electronics International (REI) The OSCOR Green was designed for commercial applications to detect illicit eavesdropping signals, perform site surveys for communications systems, conduct radio frequency (RF) emissions analysis, and investigate misuse of the RF spectrum.

AIR Patrol Corp, shared their latest in cellular detection technology.

Global TSCM Corp brought their latest technology and gave a TSCM products demo.

Professional Development TSCM Group Inc., presented on the Kestrel TSCM TM Professional Software a Canadian designed and developed TSCM total RF collection and analysis solution; scalable to address all operational threat levels.

Walleye Technologies, Inc. presented their new portable microwave imaging device for a wide variety of applications that require handheld imaging and microwave capabilities.

Other notable presentations from ERI members and TSCM Specialists included:

"The Future of TSCM" by Steve Whitehead, of Eavesdropping Detection Solutions. Gauteng, South Africa.

"GSM & Hybird Cellular Threats" by Jason Dibley & James Williams of QCC Interscan Ltd. London UK.

"TSCM" Inside Out" by Julian Claxton of Jayde Consulting Pty Ltd. Sydney, Australia

"Computer Security" by Dr. Gordon Mitchell of Future Focus, Inc. Washington State. USA.

"TSCM Challenges Today" by Ed Steinmetz of Steinmetz Associates. Philadelphia, Penn.

"Power Line Analysis using a SDR" by Michael Dever of Dever Clark & Associates of Canberra, Australia.

"Security Podcast Resources and building a network VoIP Tap" by Charles Patterson of Patterson Communications. Tarrytown, NY.

Glenn Whidden, President of ERI and a former CIA officer, created ERI in an effort to bring together TSCM specialists, security practitioners, businessmen and corporate security executives to share information about hostile global espionage activity directed against business and industry. This year’s event was chaired by J.D. LeaSure, President/CEO of ComSec LLC, which resulted in another tremendous success in bringing together this international consortium of "spy hunters". J.D. will also Chair next year’s event at ERI's Annual Membership Conference (To Be Announced). The conference will continue to highlight current and emerging threats, detection methods and effective countermeasures.

Each year, U.S. businesses lose billions of dollars to Corporate Espionage, Industrial Espionage and Economic Espionage. ERI's membership consists of a small, exclusive group of global Technical Surveillance Countermeasures (TSCM) and Cyber Counterintelligence experts whose private businesses are tasked with detecting and neutralizing the threats against your corporation.

For more information please contact ERI Conference chairman, J. D. LeaSure at: jd.leasure@espionageresearchinstitute.org or Ph: 703-910-3330

The Espionage Research Institute is dedicated to collecting and promulgating information on hostile espionage activity, which is done through the process of accepting, screening and editing reports of hostile activity as they are received from ERI Associates and its Advisors.

http://www.espionageresearchinstitute.org

Rabu, 14 September 2011

How hackers find their targets

experian.com

The rash of large-scale data breaches in the news this year begs many questions, one of which is this: how do hackers select their victims?

The answer: research.

Hackers do their homework; in fact, an actual hack typically takes place only after many hours of first studying the target.

Here’s an inside look at a hacker in action:


  1. Using search queries through such resources as Google and job sites, the hacker creates an initial map of the target’s vulnerabilities. For example, job sites can offer a wealth of information such as hardware and software platform usage, including specific versions and its use within the enterprise.
  2. The hacker fills out the map with a complete intelligence database on your company, perhaps using public sources such as government databases, financial filings and court records. Attackers want to understand such details as how much you spend on security each year, other breaches you’ve suffered, and whether you’re using LDAP or federated authentication systems.
  3. The hacker tries to identify the person in charge of your security efforts. As they research your Chief Security Officer or Chief Intelligence Security Officer (who they report to, conferences attended, talks given, media interviews, etc.) hackers can get a sense of whether this person is a political player or a security architect, and can infer the target’s philosophical stance on security and where they’re spending time and attention within the enterprise.
More...

Jumat, 09 September 2011

Researchers’ Typosquatting Stole 20 GB of E-Mail From Fortune 500 Companies

wired

Two researchers who set up doppelganger domains to mimic legitimate domains belonging to Fortune 500 companies say they managed to vacuum up 20 gigabytes of misaddressed e-mail over six months.

The intercepted correspondence included employee usernames and passwords, sensitive security information about the configuration of corporate network architecture that would be useful to hackers, affidavits and other documents related to litigation in which the companies were embroiled, and trade secrets, such as contracts for business transactions.

“Twenty gigs of data is a lot of data in six months of really doing nothing,” said researcher Peter Kim from the Godai Group. “And nobody knows this is happening.”

Doppelganger domains are ones that are spelled almost identically to legitimate domains, but differ slightly, such as a missing period separating a subdomain name from a primary domain name – as in the case of seibm.com as opposed to the real se.ibm.com domain that IBM uses for its division in Sweden.

Kim and colleague Garrett Gee, who released a paper this week (.pdf) discussing their research, found that 30 percent, or 151, of Fortune 500 companies were potentially vulnerable to having e-mail intercepted by such schemes, including top companies in consumer products, technology, banking, internet communication, media, aerospace, defense, and computer security.

More...

Jumat, 26 Agustus 2011

Engineers convicted in Goodyear corporate espionage case

tyrepress.com



A US federal judge has sentenced two former Wyko engineers to four years probation and 150 hours of community service after they were convicted of convicted of stealing trade secrets from Goodyear Tire and Rubber Co. in a corporate espionage case that first surfaced in 2009.




According to the Knoxville News Sentinel, federal prosecutors had wanted US district court judge Thomas W. Phillips to give Clark Alan Roberts and Sean Edward Howley at least 10 months in prison, but their lack of previous convictions and “ample” family and community support reportedly won out.



A jury found Roberts and Howley each guilty in December on 10-counts alleging they conspired to steal and use trade secrets. Roberts and Howley, who were employees of Wyko Tire Technology Inc. at the time, had been accused of visiting Goodyear’s Topeka, Kansas plant in 2007 so Howley could use his camera phone to take pictures OTR tyre production procedures.



During the trial Tom Frey, a consultant for Goodyear and a former Goodyear manager, had estimated it cost $520,000 to develop the design drawings for the equipment the defendants were convicted of photographing and that Goodyear made $17 million in 2007 from the sale of tyres that machine produces. However Judge Phillips rejected Frey as a witness and noted that he was not employed by Goodyear and had not produced documentation to verify these figures.



More...


Rabu, 17 Agustus 2011

Corporate cybercrime tops boardroom agenda

freshbusinessthinking.com



High profile corporate cybercrime is putting information security on boardroom agendas around the world, a global survey revealed on Wednesday.



The need for increased measures to protect against corporate espionage and network hacking, the accidental or deliberate leaking of corporate data, and the loss or theft of company laptops, has never been so high, company bosses told the British Standards Institution (BSI), the leading business service for the development of standards, in a survey.



According to the research, which analyses responses from 645 businesses, risk of corporate data leaks is a key concern. Two thirds (64%) of the surveyed businesses that have implemented ISO 27001 (an information security management system) cited this as the most important driving force behind adopting the information security standard.



In addition to risk, the BSI research also shows that 72% of businesses are worried about the financial damage of cybercrime.



More...

Related Posts Plugin for WordPress, Blogger...